The Flower team is excited to announce the release of Flower 1.37 stable, packed with new updates!
Flower is a friendly framework for collaborative AI and data science.
It makes novel approaches such as federated learning, federated evaluation,
federated analytics, and fleet learning accessible to a wide audience of researchers and engineers.
Thanks to our contributors
We would like to give our special thanks to all the contributors who made the new version of Flower possible (in git shortlog order):
Charles Beauville, Chong Shen Ng, Daniel J. Beutel, Daniel Nata Nugraha, Dimitris Stripelis, Heng Pan, Javier, Julian Rußmeyer, Paul Thomas, Silvio Cretti, Taner Topal, Zhewen Tan
What’s new?
With this release, both RuntimeAPI and ControlAPI now use HTTP, making traffic easier to inspect, debug, and integrate with standard HTTP tooling. Logging is also richer, and the default log output has changed slightly to improve readability. To see all logs, enable verbose logging for SuperLink, SuperNode, or SuperExec. SuperLink no longer periodically logs which SuperNodes are connected; you can query this information at any time by running flwr supernode ls.
-
Flower CLI switches to HTTP (#8028, #8045, #8046, #8047, #8055, #8057, #8070, #8072, #8073, #8076, #8077, #8084, #8085, #8087, #8089, #8093, #8099)
The Flower CLI now sends Control API requests over HTTP. The gRPC Control API is disabled by default, and
--control-api-addressis deprecated in favor of--hostand--port. SuperGrid configuration and deployment guides now useapi.flower.ai. If your Flower Configuration file defines a customSuperLinkconnection, you must update it for the switch from gRPC to HTTP; in most cases, only the port needs to change. -
Improve AgentApp conversations with history, connectors, titles, and local app loading (#8048, #8058, #8060, #8101, #8102, #8104, #8105, #8110, #8123, #8127, #8128, #8131, #8133, #8148)
flwr chatcan now load and interactively test local AgentApps with the/load <path>command. Users can name or rename conversation titles, and titles can also be generated automatically. Within anAgentApp, persisted conversation history is now accessible throughagent.events.get_trace(), with user inputs and tool calls recorded as standard events.flwr chatcan also use connected connectors: select them with/connector, view the current selection in the context bar, and clear it with/connector clear. Connector setup remains available through the Web UI. -
Configure Runtime API TLS with consistent options (#8109, #8113)
SuperNode now uses
--ssl-certfile,--ssl-keyfile, and--ssl-ca-certfilefor Runtime API TLS while retaining the former--appio-ssl-*options as deprecated aliases. SuperLink help now clarifies that the same--ssl-*options secure its Fleet, Control, and Runtime APIs. -
Deploy SuperNodes using Slurm (#8074)
A new guide covers running SuperNodes as Slurm jobs with subprocess or process isolation, including separate SuperExec jobs, GPU allocation, and scheduler-selected nodes.
-
Reject invalid
FedTrimmedAvgtrimming fractions (#7946)ServerApp and legacy
FedTrimmedAvgstrategies now requirebetato be in[0, 0.5), preventing invalid trimming from producingNaNmodel parameters. -
Run adaptive federated DDoS attack detection with FLAD (#8083)
The new FLAD baseline implements the strategy and a subset of the convergence experiments from its paper on a highly non-IID dataset of heterogeneous DDoS attacks. FLAD dynamically assigns more computation to clients whose attack profiles are harder to learn without sharing test data.
-
General improvements (#8049, #8056, #8064, #8066, #8067, #8068, #8071, #8075, #8078, #8080, #8082, #8088, #8095, #8096, #8098, #8103, #8108, #8112, #8114, #8115, #8116, #8118, #8119, #8120, #8124, #8125, #8126, #8129, #8134, #8135, #8136, #8137, #8139, #8140, #8142, #8144, #8149)
As always, many parts of the Flower framework and quality infrastructure were improved and updated.
Incompatible changes
-
Remove deprecated SuperLink Exec API options (#8100)
SuperLink no longer accepts
--exec-api-address,--executor,--executor-dir, or--executor-config. Remove these long-deprecated options from SuperLink launch configurations. -
Update SuperLink TLS configuration (#8106)
SuperLink now uses
--ssl-certfile,--ssl-keyfile, and--ssl-ca-certfileto secure its Fleet, Control, and Runtime APIs with one certificate set. Replace any--appio-ssl-*options with these shared options; the removed flags now terminate startup.
